Privacy Policy

Last updated: 26 April 2026

This Privacy Policy explains how 360 QHSE Ltd collects, uses, stores, and protects your personal data when you use the 360 QHSE platform and website.

1. Who We Are

360 QHSE Ltd ("we", "us", "our") is the data controller responsible for your personal data. We are registered in Scotland and are registered with the Information Commissioner's Office (ICO).

Registered address: Walter Street, Glasgow, G31 3PR, United Kingdom

Data Protection contact: [email protected]

Phone: +44 7368 303370

2. Personal Data We Collect

We collect personal data in the following categories:

CategoryExamplesPurpose
Account dataName, email address, job title, company nameAccount creation and authentication
Usage dataPages visited, features used, session duration, IP addressPlatform improvement and security
QHSE recordsIncident reports, audit records, risk assessments you createProviding the core platform service
Payment dataBilling name, address, last 4 digits of card (processed by Stripe)Processing subscription payments
CommunicationsSupport emails, demo requests, feedback submissionsCustomer support and product development
Technical dataBrowser type, device type, operating system, cookiesSecurity, analytics, and performance

3. Legal Basis for Processing

Under UK GDPR, we rely on the following lawful bases:

  • Contract performance (Art. 6(1)(b)): Processing your account data and QHSE records to deliver the service you have subscribed to.
  • Legitimate interests (Art. 6(1)(f)): Analysing usage patterns to improve the platform, preventing fraud, and sending product updates to existing customers.
  • Legal obligation (Art. 6(1)(c)): Retaining financial records as required by UK tax law (HMRC — 6 years).
  • Consent (Art. 6(1)(a)): Sending marketing emails to prospective customers and placing non-essential cookies. You may withdraw consent at any time.

4. How We Use Your Data

  • Provide, operate, and maintain the 360 QHSE platform
  • Process your subscription payments securely via Stripe
  • Send transactional emails (account confirmations, password resets, invoices)
  • Respond to support requests and demo enquiries
  • Monitor platform performance, uptime, and security
  • Comply with legal and regulatory obligations
  • Send product updates and feature announcements (you may unsubscribe at any time)
  • Conduct anonymised analytics to improve the platform

5. Who We Share Your Data With

We do not sell, rent, or trade your personal data. We share data only with trusted third-party processors under written data processing agreements:

ProcessorPurposeLocation
Stripe Inc.Payment processingUSA (Standard Contractual Clauses)
TiDB Cloud (PingCAP)Database hostingEU/UK
Google (Gmail SMTP)Transactional email deliveryEU
Tawk.toLive chat supportUSA (Standard Contractual Clauses)
CloudflareCDN, DDoS protection, DNSEU/UK

Where data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses or adequacy decisions).

6. Data Retention

Data TypeRetention Period
Active account dataFor the duration of your subscription
QHSE records (incidents, audits, risks)7 years after account closure (legal/regulatory requirement)
Payment records6 years (HMRC requirement)
Support communications3 years
Marketing consent recordsUntil consent is withdrawn + 1 year
Server logs and security data90 days
Anonymised analyticsIndefinitely (no personal data retained)

7. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

Right of access

Request a copy of all personal data we hold about you (Subject Access Request).

Right to rectification

Ask us to correct inaccurate or incomplete personal data.

Right to erasure

Request deletion of your personal data where there is no compelling reason for continued processing.

Right to restriction

Ask us to restrict processing of your data in certain circumstances.

Right to data portability

Receive your data in a structured, machine-readable format.

Right to object

Object to processing based on legitimate interests or for direct marketing.

Right to withdraw consent

Withdraw consent at any time where processing is based on consent.

Right to complain

Lodge a complaint with the ICO at ico.org.uk or call 0303 123 1113.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.

8. Cookies

We use cookies and similar tracking technologies on our website. For full details of the cookies we use, their purpose, and how to manage them, please see our Cookie Policy.

9. Security

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include AES-256 encryption at rest, TLS 1.3 in transit, role-based access control, and regular security reviews. For full details, see our Security page.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay.

10. Children's Data

The 360 QHSE platform is a business-to-business service intended for use by organisations and their employees. We do not knowingly collect personal data from individuals under the age of 16. If you believe we have inadvertently collected such data, please contact us immediately at [email protected].

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

12. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please contact our Data Protection team:

Email: [email protected]

Post: Data Protection, 360 QHSE Ltd, Walter Street, Glasgow, G31 3PR, UK

Phone: +44 7368 303370

You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk.

© 2026 The Horn Integrated QHSE Solutions Ltd · Registered in Scotland
360QHSE Ltd registered with the ICO · Data stored on UK servers · UK GDPR compliant